Technical Information
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\RunOnce] '1989' = '%TEMP%\1989\jPLXDPwm.exe'
- hidden files
- '%WINDIR%\Microsoft.NET\Framework\v2.0.50727\RegSvcs.exe'
- %WINDIR%\Microsoft.NET\Framework\v2.0.50727\RegSvcs.exe
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer] 'NoFolderOptions' = '00000001'
- %APPDATA%\23EF5514-3059-436F-A4A7-4CEFAAB20EB1\run.dat
- %HOMEPATH%\dMoKwQbvj.txt
- %HOMEPATH%\dMoKwQbvj.txt
- 'vi######ing89.duckdns.org':1608
- DNS ASK vi######ing89.duckdns.org
- ClassName: 'Indicator' WindowName: ''